Risk culture
RISK CULTURE
The company’s encourages the development of a risk management culture across all levels of the organization, instilling a consciousness among executives and employees alike about the significance of risk management. This culture pervades the entire organization and is sustained over time, ensuring that risk management practices are carried out effectively and efficiently. The company‘s risk management policy is communicated across the company through our internal website, accessible to all employees. The company lays the foundation for systematic risk management by adhering to international standards, in order to apply risk management systems effectively and efficiently to business operations. Through the efforts of various committees, the company can promptly identify business risks or opportunities as they arise and devise practical risk management strategies. The framework for risk management is as follows:
- Review the risk management policy and the acceptable level of risk (Risk Appetite) annually, and communicate this to executives, employees at all levels, and all units across the organization. This is to ensure that both management and employees are aware of the potential risks, the impacts arising from those risks, the importance of risk management, and their shared responsibility towards risk. Additionally, integrate the risk management policy into daily operations, using it as a guideline for decision-making and planning.
- Mandate the consideration of integrated risk assessment alongside strategic planning, performance results, and the overall Risk Profile of the organization. Promote understanding of Risk Appetite among relevant departments or units for use in evaluation, planning, and management actions.
- Apply the result of Maturity Assessment for organizational risk management to ensure ongoing and efficient implementation. Promote the integration of operational lines by following the Three Lines of Defense approach to mitigate risks, reduce operational errors, and to support the organization’s strategic objectives and enhancing stakeholder confidence.
- Define guidelines to develop Risk Champions for each operational line, representing their units in coordinating and monitoring the implementation of risk management plans.
- Advocate for policies that foster the development of skills, knowledge, and understanding of risk management, emphasizing the importance of related certifications to ensure competent and effective advice is provided to the management and staff.
- Continuously improves and refines its risk information database, providing a robust platform for the collection, monitoring, analysis, and reporting of data, ultimately facilitating effective risk management decisions.